On CBS MoneyWatch: Selling a house? 6 tips for a great ad
BNET Business Network:
BNET
TechRepublic
ZDNet

By Colin Barker
Posted on ZDNet News: Aug 22, 2006 9:31:00 PM

Malicious code that exploits a recent Windows hole has led to significant growth in the number of hijacked PCs, according to messaging security company CipherTrust.

On Tuesday, CipherTrust reported a 23 percent growth in the total number of so-called zombie PCs it has detected. The jump is due to the spread of Mocbot worm variants, CipherTrust said. Mocbot, also known as Cuebot and Graweg, exploits a Windows security flaw for which Microsoft issued a patch with security bulletin MS06-040 on Aug. 8.

"Around Aug. 13, the weekend after Black Tuesday, we started seeing a gradual increase in the average number of new zombies," said Dmitri Alperovitch, a research scientist at CipherTrust in Alpharetta, Ga. "It went up from 214,000 every day in the previous week to 265,000 every day."

Any computer infected by Mocbot will become part of a botnet, a large network of compromised PCs that can be controlled remotely to carry out tasks such as sending spam. In June, Microsoft warned that the threat posed by botnets and zombies was growing fast.

CipherTrust can trace the increase in spam-sending zombies to Mocbot by comparing junk e-mail sent by systems it knows were compromised by the worm to the spam sent by new zombies, Alperovitch said. "They are mostly Rolex spam and porn spam, and they are the same messages that are being sent by these new zombies coming online," he said.

Alperovitch estimated that somewhere between 500,000 and 1 million machines were hijacked by Mocbot. As a result, more junk mail is soiling the Internet, with spam making up 81 percent of all mail volume this week. "I would not say this has been a huge outbreak, but it has been a noticeable change," he said.

Security experts had said that the MS06-040 worm appeared to be limited in its spread and only hitting computers running Windows 2000.

Colin Barker of ZDNet UK reported from London.

Malicious code that exploits a recent Windows hole has led to significant growth in the number of hijacked PCs, according to messaging security company CipherTrust.

On Tuesday, CipherTrust reported a 23 percent growth in the total number of so-called zombie PCs it has detected. The jump is due to the spread of Mocbot worm variants, CipherTrust said. Mocbot, also known as Cuebot and Graweg, exploits a Windows security flaw for which Microsoft issued a patch with security bulletin MS06-040 on Aug. 8.

"Around Aug. 13, the weekend after Black Tuesday, we started seeing a gradual increase in the average number of new zombies," said Dmitri Alperovitch, a research scientist at CipherTrust in Alpharetta, Ga. "It went up from 214,000 every day in the previous week to 265,000 every day."

Any computer infected by Mocbot will become part of a botnet, a large network of compromised PCs that can be controlled remotely to carry out tasks such as sending spam. In June, Microsoft warned that the threat posed by botnets and zombies was growing fast.

CipherTrust can trace the increase in spam-sending zombies to Mocbot by comparing junk e-mail sent by systems it knows were compromised by the worm to the spam sent by new zombies, Alperovitch said. "They are mostly Rolex spam and porn spam, and they are the same messages that are being sent by these new zombies coming online," he said.

Alperovitch estimated that somewhere between 500,000 and 1 million machines were hijacked by Mocbot. As a result, more junk mail is soiling the Internet, with spam making up 81 percent of all mail volume this week. "I would not say this has been a huge outbreak, but it has been a noticeable change," he said.

Security experts had said that the MS06-040 worm appeared to be limited in its spread and only hitting computers running Windows 2000.

Colin Barker of ZDNet UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 81 Talkback(s)
Been running LUA for years now...
Amazing how well it works so far. But then, the vulnerability being discussed will nail you no matter what security level you are running on Windows XP/Server 2003. And if you are running Linux, the s... (Read the rest)
Posted by: Boomslang Posted on: 08/27/06 You are currently: a Guest | | Terms of Use
Worm Sparks Rise In Zombie PCs  itanalyst | 08/22/06
I give you a seven for trying ,,,  Intellihence | 08/22/06
worms...etc.  ohaspider | 08/22/06
unfortunately there already is  alandee4 | 08/23/06
um.....  Suicida| | 08/23/06
sender and domain fake, why not rply-to?  Still Lynn | 08/23/06
The heading of this story should read" Worm sparks rise in MS zombie PCs .  Intellihence | 08/22/06
How bout "Worm sparks rise in UNPATCHED zombie PCs"  PB_z | 08/22/06
How bout "Worm sparks rise in UNPATCHED MS zombie PCs"  Intellihence | 08/22/06
garbage posts  steveh99 | 08/23/06
Plain ignorance of Different OS Architectures  LinuxUser&XPGamerGraphic | 08/23/06
Not completely true  rpmyers1 | 08/24/06
MAC attack !  chuck@... | 08/23/06
That is an opinion from a non-technical user.  LinuxUser&XPGamerGraphic | 08/23/06
Not News  Kobashrer | 08/22/06
hah  kielork | 08/23/06
Worm sparks rise in zombie PCs  Loverock Davidson | 08/22/06
...home users have autoupdate on...  swoopee | 08/23/06
Really  Loverock Davidson | 08/23/06
and what about...  vmtnezgil@... | 08/23/06
What about them?  Loverock Davidson | 08/23/06
The point is ISP or subscriber responsability?  vmtnezgil@... | 08/23/06
I may be wrong  swoopee | 08/23/06
Auto Update not a panacea  MacCanuck | 08/23/06
Autoupdate works fine  Loverock Davidson | 08/23/06
In your dreams happy  MacCanuck | 08/23/06
Dreams turn into reality  Loverock Davidson | 08/23/06
Considering people's reliance on the Internet  MacCanuck | 08/23/06
Your own comments about Updates  slim-01 | 08/23/06
Administrators, or MS?  rpmyers1 | 08/23/06
Correction: Ed Bott's article  rpmyers1 | 08/23/06
All is hopeless  Carrion | 08/23/06
Hmm  Krazyken39 | 08/23/06
fascinating...  Carrion | 08/23/06
Do you even use Linux?  slim-01 | 08/23/06
On the nose!  handydan918 | 08/23/06
Hope you have better luck than I do...  LuckyCharm | 08/23/06
It's not hopeless, but it IS a pain ...  kennedym@... | 08/23/06
Been running LUA for years now...  Boomslang | 08/27/06
MS Champs at breaking their OS, cant say crap w/mouthful  jonathan swift | 08/23/06
The only victims  ctm66446 | 08/23/06
So true on so many points,  Boot_Agnostic | 08/23/06
Reality.....  john_galt@... | 08/23/06
And this makes you superior because?  orangemike | 08/23/06
Just not in that group  ctm66446 | 08/23/06
Bull  Boot_Agnostic | 08/24/06
And do what with it...  ctm66446 | 08/24/06
It makes a wonderful fallback  Boot_Agnostic | 08/24/06
The Windblows at Microsucts  This501 | 08/23/06
how does it not work?  ctm66446 | 08/23/06
your money  steveh99 | 08/23/06
Put "Bottom Line" in First Paragraph!  archetuthus | 08/23/06
i agree with you  ctm66446 | 08/23/06
Worm Compromised PC's  zeghost@... | 08/23/06
Charge for each email!  meperr8@... | 08/23/06
Charge for each mail  mebejb | 08/23/06
Church of the Painful OS  Reverend MacFellow | 08/23/06
Amen, brother!  orangemike | 08/23/06
What of the Mac resurrection?  oldradiojock | 08/23/06
Server side or client side?  vmtnezgil@... | 08/23/06
ISP's  john_galt@... | 08/23/06
thought?  vmtnezgil@... | 08/23/06
I don't want to pay my ISP extra...  mdsmedia | 08/23/06
the cost should fall on the culprit - the dumb user who has the bot.  Castanet | 08/23/06
Would you still boil water before drinking?  vmtnezgil@... | 08/24/06
Do people still use windows  IceTheNet@... | 08/23/06
As much as MS monopoly causes issues  davidnewman7798@... | 08/23/06
Lame  kielork | 08/23/06
Why is it Lame?  isawyoo1st@... | 08/23/06
um  kielork | 08/23/06
um  steveh99 | 08/23/06
UMM & then....  oldradiojock | 08/23/06
You not having a problem  rpmyers1 | 08/23/06
you've been hacked  will.be.deleted@... | 08/23/06
Misleading ZDNet stories  bernie157 | 08/23/06
Worm is sparked by greed & vandals  oldradiojock | 08/23/06
Wrong focus, folks  qhris@... | 08/23/06
Best OS? As compared to what?  oldradiojock | 08/23/06
I've never bashed MS...  mdsmedia | 08/23/06
MS software is what it is  Boot_Agnostic | 08/24/06
The only reason Microsoft is trying at all  slim-01 | 08/24/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Introducing SmartPlanet

  • Find thought-provoking progressive ideas on topics that intersect with technology, business and life. Visit Today
  • Technology, perspective, and insights shaping the world
  • Learn innovative and practical skills for your business and your life. SmartPlanet offers 360 degree coverage that you need to feel connected to the information that matters to the world at large. Go to SmartPlanet
advertisement
Click Here